Back to Student Housing

GDPR Compliance

I. What Is the GDPR

The General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") is the European Union's framework for the protection of personal data. It applies to the processing of personal data of individuals in the European Union and European Economic Area, regardless of where the organization processing that data is established. This page explains, pillar by pillar, how TINT TECH S.R.L. complies with the GDPR in operating the Student Housing website and mobile application (together, the "Service"). Where a category-specific detail (such as retention periods or the identity of a specific recipient) is involved, it is set out in the Privacy Policy, which this page cross-references throughout.

II. Data Controller

The data controller responsible for your personal data is TINT TECH S.R.L. Its registration details are set out in the Legal Notice. For any question about the processing of your personal data, you may contact the Controller at contact@tinttechhub.com.

III. Core Principles of Processing (Article 5)

Article 5 of the GDPR sets out the principles that govern all of our processing of personal data:

  • Lawfulness, fairness, and transparency — we process data only on a valid legal basis (Section IV) and tell you what we do with it, here and in the Privacy Policy.
  • Purpose limitation — we collect data for specified, explicit purposes and do not process it further in a way incompatible with those purposes.
  • Data minimisation — we collect only the data needed for each function of the Service; most profile fields are optional.
  • Accuracy — you can correct inaccurate data at any time from your account settings.
  • Storage limitation — we keep data only for as long as necessary, as described in Section VIII of the Privacy Policy.
  • Integrity and confidentiality — we apply technical and organizational security measures described in Section VIII below.
  • Accountability — we are responsible for, and must be able to demonstrate, compliance with these principles (Section XII below).

IV. Legal Basis for Processing (Article 6)

We only process your personal data where at least one of the following applies:

  • Consent (Article 6(1)(a)) — for example, the waitlist email address, optional profile fields, device location access, and ad personalization. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Performance of a contract (Article 6(1)(b)) — account data and the core functions of the Service you request when you create an account.
  • Legitimate interest (Article 6(1)(f)) — fraud and abuse prevention, crash reporting, and reviewing reports, balanced against your fundamental rights.

V. Special Categories of Data (Article 9)

Article 9 of the GDPR gives extra protection to special categories of data — such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. We do not intentionally collect or request any special category data through the Service. Lifestyle preferences you may choose to share for roommate matching (such as smoking habits or quiet hours) are ordinary personal data, not special category data. Please do not include special category data in free-text fields such as your bio or messages.

VI. Children's Data (Article 8)

The Service is intended for university students and other adults. In line with Article 8, we do not knowingly collect personal data from anyone under 16, or such higher age of consent as may apply under the law of your habitual residence. If we learn that an account has been created by a person below the applicable age, the account is deactivated and the associated data deleted, as described in Section XI of the Privacy Policy.

VII. Data Protection by Design and by Default (Article 25)

We aim to build data protection into the Service rather than add it afterward. In practice, this means: most profile fields are optional and off by default; database access rules restrict each category of data to the users who need it (for example, only the participants in a conversation can read its messages); precise device location is used transiently for search and is not stored against your profile; and account deletion is designed to remove data across the Service, not just your visible profile.

VIII. Security of Processing (Article 32)

We use technical and organizational measures appropriate to the risk, including encryption in transit and at rest, hashed passwords never accessible to us in plain text, and database access rules scoped to each category of data. The full description of these measures is set out in Section X of the Privacy Policy.

IX. Personal Data Breach Notification (Articles 33–34)

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay, as required by Article 34.

X. Processors and International Transfers (Articles 28, 44–50)

Where we use other companies to process personal data on our behalf (processors), we do so under a data-processing agreement that requires them to process data only on our instructions and to apply appropriate security measures, as required by Article 28. Our processors include Google Firebase (infrastructure), Google AdMob (advertising), and our email-delivery and hosting providers.

These providers may process and store personal data outside the European Economic Area, including in the United States. Where this happens, we rely on the transfer safeguards recognized under Chapter V of the GDPR that our providers implement, such as the EU–U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.

XI. Data Protection Officer (Articles 37–39)

Under Article 37, a Data Protection Officer must be appointed only where an organization's core activities involve large-scale systematic monitoring of individuals or large-scale processing of special category data. Given the nature and scale of our processing, TINT TECH S.R.L. is not currently required to appoint a Data Protection Officer. Questions about data protection can be addressed directly to the Controller at contact@tinttechhub.com, and we will reassess this position if our processing activities change.

XII. Accountability and Records of Processing (Articles 5(2), 24, 30)

We are responsible for demonstrating compliance with the principles in Section III. In practice, this includes maintaining a record of our processing activities describing the categories of data, purposes, recipients, and retention periods referenced throughout this page and the Privacy Policy; reviewing our practices as the Service evolves; and requiring our processors to provide sufficient guarantees under Article 28.

XIII. Your Rights Under the GDPR (Articles 12–22)

As a data subject, you have the following rights, at no cost, unless a request is manifestly unfounded or excessive:

  • Right to be informed — to know what data we process about you and why, as described in the Privacy Policy and this page.
  • Right of access — to obtain a copy of the personal data we hold about you.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure ("right to be forgotten") — to have your personal data deleted, subject to certain legal exceptions.
  • Right to restriction of processing — to limit how we use your data in certain circumstances.
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format.
  • Right to object — to object to processing based on legitimate interest, including for direct marketing.
  • Right to withdraw consent — at any time, where processing is based on consent.
  • Rights related to automated decision-making — we do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
  • Right to lodge a complaint — with your national data protection authority; in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP).

XIV. How to Exercise Your Rights

Most rights can be exercised directly:

  • Access, correct, or delete most account and profile data directly from the application's account settings.
  • Export a copy of your data using the export function available within the application.
  • Request account and data deletion through student-housing.app/delete-account.
  • For anything else — including access requests, objections, or complaints — email contact@tinttechhub.com. We will respond within one month, as required by Article 12 of the GDPR, extendable by two further months for complex requests.

XV. Related Documents

The complete legal description of our data processing — including categories of data, recipients, retention periods, and international transfers — is set out in the Privacy Policy. Our company registration details are set out in the Legal Notice.